Executive brief
IBM i is a business-critical operating system used by enterprises for running mission-critical applications. This vulnerability allows a remote attacker without authentication to bypass the system's security controls by exploiting improper validation of user-supplied addresses, potentially leading to unauthorized data access, system modification, or service disruption. IBM has released patches for all affected versions and recommends immediate remediation.
Technical details
The vulnerability exists in IBM i's improper validation of user-controlled addresses (CWE-269: Improper Privilege Management), allowing an unauthenticated remote attacker to bypass security restrictions. The attack has a high complexity factor but requires no user interaction and can impact multiple security goals (confidentiality, integrity, and availability) across system boundaries. An attacker can exploit this to gain unauthorized access to sensitive data or compromise system integrity. IBM has provided multiple PTFs (Program Temporary Fixes) for versions 7.3, 7.4, 7.5, and 7.6, available through IBM's support portal.
Affected products
- IBM IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-13: disclosed